Who we are and what this covers
Brightwave Products Inc. operates PackMagic. This policy describes personal information handled through our iOS app, public website, community features, transactions, and support. Contact support@usebrightwave.com with privacy questions or requests.
The public website currently provides information and legal documents. It does not offer account registration or checkout. Some app features described below depend on account eligibility and service availability. Describing a feature here does not mean it is currently enabled.
Account and contact information
Depending on how you sign in, we receive your email address, phone number, account identifier, authentication status, and information supplied by a sign-in provider. Email and password sign-in uses Supabase Auth. Phone sign-in uses verification messages through our authentication provider and Twilio. If Apple or Google sign-in is offered and you choose it, we receive the account information that provider makes available, such as your identifier, name, and email address. Apple may supply a private relay address.
We keep the display name, biography, avatar and cover choices, uploaded profile photos and banners, profile visibility, follows, and showcase cards you select. Eligibility records can include your state and whether an adult or eligibility check has been completed. The app does not currently collect identity-document images or a date of birth through a verification flow. If a future verification service requires additional information, we will explain that collection before you submit it.
When you contact support, we receive your message, contact information, attachments you choose to send, and the order or account references needed to help you. Do not send passwords, sign-in codes, full payment-card numbers, or identity documents by ordinary email.
Collections, purchases, and shipping
We record gem balances and their sources, orders and payment references, payment and refund status, disputes, opening attempts, odds and verification receipts, awarded cards, card exchanges, collection locks, rewards, XP, and published vaults. These records let us recover interrupted actions, verify outcomes, and resolve ownership or payment questions.
When checkout is available, payment details are entered with the payment processor. The implemented processor is Stripe. PackMagic receives transaction references, amounts, currency, and payment status; the app does not receive or store your full card number or security code. A processor can collect billing, device, and fraud-prevention information under its own privacy notice.
For physical delivery, we collect the recipient name, street address, apartment or unit, city, state, ZIP code, selected cards, shipping quote, tracking information, delivery status, and related support records. We use this information to quote, arrange, and resolve shipments.
Community information and public profiles
Profiles are public by default. A public profile can show your display name, biography, avatar, cover, join date, game statistics, XP, collector level, public follower and following lists, chosen showcase cards, and published vaults. Eligible public activity can appear in Top wins and leaderboards. We do not include your account email, delivery address, private account identifier, or full private collection in these public views.
Turn off Public profile in Edit profile to hide your player page, leaderboard entries, and Top wins from subsequent refreshes. Your name, profile photo and level remain visible with chat messages. Uploaded profile images can be viewed by anyone with their image link. Choosing a default image detaches the uploaded picture from your profile; it does not delete copies already shared or stored. This setting does not make your chat messages private, remove other people's screenshots, or automatically withdraw vaults you have published.
Chat messages, selected GIFs, replies, and reward-event participation can be visible to other signed-in members. Event displays can include participant names, avatars, and awarded gems. We also record recent chat presence, blocked accounts, reports, and moderation actions. Chat is a shared community space and is not an end-to-end encrypted private messenger.
We use automated text rules and human review to address abusive content. Current text filters can replace prohibited words before a message is stored. Reports and necessary case records may remain after a message is removed from the feed.
Device, network, and local information
Our hosting and infrastructure providers process IP addresses, request times, requested resources, device or browser information sent with a request, and operational or security logs. An IP address can indicate an approximate location. The current app does not request GPS location, contacts, microphone access, or an advertising identifier.
The app stores sign-in session tokens in the iOS Keychain. It stores preferences, onboarding progress, favorites, drafts, and recovery information on your device. Demo cards, simulated balances, and demo progress stay on that device and do not become live awards. Network requests for remotely loaded content can still occur when you use the app.
If you enable shipment notifications and the service is available, we register an Apple push token with your account, device environment, and notification preference. Notification delivery uses Apple Push Notification service. You can change the app's shipment setting and iOS notification permissions. A notification already submitted to Apple may still arrive after you turn notifications off.
Cookies and third-party media
Our public policy website does not currently add analytics, advertising cookies, or marketing pixels. Its fonts and brand artwork are served with the site. Hosting still involves the network information described above. The app uses local storage for its functions; a provider's checkout, sign-in page, or linked website may use its own cookies.
Chat GIFs and previews load directly from media.giphy.com. Loading a GIF sends GIPHY your IP address and the network information needed to retrieve that image, even if you do not have a GIPHY account. PackMagic does not send your account email, delivery address, or gem balance as part of that image request. GIPHY's independent use of information is described in its privacy policy. Hide GIFs in Chat settings to avoid loading GIFs in the message feed; opening the GIF picker can still load previews. Turning off autoplay alone does not prevent an image request.
PackMagic does not run a behavioral advertising program or sell account information for money. That statement does not describe every third-party provider's independent practices. The classification of third-party media disclosures under state sale, sharing, and targeted-advertising rules must be resolved before this draft becomes effective. We do not currently change the website's behavior in response to a browser Do Not Track signal.
How we use information
We use information to authenticate accounts, maintain collections and balances, check eligibility, settle and verify openings, process purchases and refunds, arrange shipping, deliver requested service messages, and answer support requests. We also use it to operate profiles and chat, moderate content, prevent fraud and duplicate claims, secure the service, diagnose failures, keep necessary business records, and comply with applicable law.
Providing information needed for an account, payment, eligibility decision, or delivery is necessary to complete that action. Profile biographies, showcase selections, chat participation, and push notifications are optional. We do not use the personal information described here to train a general-purpose AI model.
Who receives information
Supabase supplies authentication, database, storage, and backend services. Vercel hosts the public website and operator console. Twilio handles phone verification when that sign-in method is used. Stripe processes payments when enabled. Apple and Google receive information when their sign-in services are used, and Apple handles enabled push notifications. The transactional-email integration uses Amazon Web Services, including Amazon SES, when configured, to send service messages and process delivery, bounce, and complaint events.
Delivery and fulfillment providers receive the details needed to source, pack, deliver, and resolve your shipment. Staff and support providers can access information needed for their work. Other collectors receive the public and community information described above. GIPHY receives requests for its media.
We may disclose information where reasonably necessary to comply with a lawful request, protect people and property, investigate fraud, establish or defend legal claims, or carry out a corporate transaction with appropriate confidentiality protections. We may also share information at your direction. Independent services, including carriers, sign-in providers, and payment processors, can have their own legal duties and retention practices.
Retention and deletion
We retain account information while needed to provide the service and handle the obligations described in this policy. Retention decisions consider the record's purpose, outstanding cards or balances, shipments, disputes, security needs, applicable law, and provider requirements. These reasons apply to the relevant records and do not justify keeping unrelated personal information indefinitely.
The current account-deletion workflow removes access and scrubs mutable profile, address, chat, and device data after review. It also removes uploaded profile images and follows. It retains a private account identifier, transaction and opening records, payment and fulfillment evidence, published version history, and deletion or operator audit records. Some historical text can still contain personal information. These retained records are not automatically anonymous.
A retention review is scheduled 30 days after an operator approves deletion. That is a review date, not a promise that all records are automatically erased after 30 days. The final category-specific retention periods, backup expiration, and disposal process remain under review. No seven-year financial period or 35-day backup expiration is currently promised by this draft.
Deleting data from PackMagic does not necessarily erase copies independently retained by providers or other people. We will apply legally required deletion instructions and explain any applicable exception when handling your request.
Your choices and privacy requests
You can edit your profile, change its visibility, delete your own chat messages, manage blocked members and GIF settings, and change notification preferences. To request account deletion, use Profile, open Settings with the gear button, and select Request account deletion. If you cannot access the app, email support@usebrightwave.com.
Depending on your location and which laws apply to PackMagic, you may have rights to know about our processing, access or obtain a portable copy of information, correct it, delete it, or opt out of certain processing. Some state laws also provide an appeal, an authorized-agent process, or rights concerning sensitive information and qualifying universal opt-out signals. These rights depend on statutory coverage and exceptions; this draft does not claim that every state law applies to us.
Send a request to support@usebrightwave.com with the subject Privacy request and enough information to identify your account and request. We may verify identity or an agent's authority using information appropriate to the request. We will not ask for your password or a sign-in code by email. We will respond within the applicable legal deadline and explain a denial or extension. If you disagree with a decision, reply with Privacy appeal so we can review it. We will not penalize you for exercising an applicable privacy right.
Children, security, and processing locations
PackMagic is intended for adult collectors. It is not directed to children, and we do not knowingly permit children under 13 to create accounts. If you believe a child has supplied personal information, contact us so we can investigate and take appropriate deletion steps. Our minimum age is 18, or any higher age required by applicable law. Approved locations will be stated in the effective rules before prize play opens.
We use access controls and technical safeguards appropriate to the service. No storage or transmission system is guaranteed secure. Protect your device and account, and tell us if you suspect unauthorized access.
PackMagic is designed for approved locations in the United States. Our providers may process information in the United States and other countries where they operate. Access to the informational website does not establish eligibility for the app. This draft does not announce availability in the European Economic Area, United Kingdom, or other unapproved markets.
Changes and contact
When this policy becomes effective, we will show its effective date here. Later revisions will show a new date. For material changes, we will provide additional notice where appropriate or required, and obtain consent where the law requires it. Questions about this draft can be sent to Brightwave Products Inc. at support@usebrightwave.com.